Why Nexovern
Support Request a demo

Home  /  Resources  /  Frameworks  /  IRDAI

IRDAI cybersecurity and AI governance for insurance: the regulatory bar keeps rising

India's insurance regulator has built a layered compliance framework spanning 24 security domains, mandatory data localization, six-hour incident reporting, and board-level accountability for cybersecurity. With the 2025 Insurance Amendment Act raising penalties tenfold and a dedicated AI Governance Working Group now drafting India's first formal AI framework for insurance, every regulated entity deploying AI agents faces a compliance landscape that grows more demanding each quarter.

What IRDAI requires, and why it matters now

The Insurance Regulatory and Development Authority of India (IRDAI) is the statutory body established under the IRDAI Act, 1999 to regulate India's insurance and reinsurance industries. Since 2023, IRDAI has issued a rapid succession of cybersecurity guidelines, corporate governance regulations, data localization mandates, and crisis preparedness circulars that collectively create one of the most prescriptive compliance frameworks in Asia's financial services sector. The June 2026 announcement of a seven-member AI Governance Working Group, chaired by Sandeep K. Shukla (Director, IIIT Hyderabad) with IRDAI CISO Deepak Gaikwad as Member Convener, signals that formal, binding AI governance requirements for insurance are months away.

Rs 10 Cr

maximum penalty per violation under the 2025 Insurance Amendment Act, a tenfold increase from the previous Rs 1 crore cap

Insurance Amendment Act, 2025

6 hrs

deadline to report cyber incidents to both IRDAI and CERT-In after detection, tightened from the earlier 24-hour window

IRDAI Cyber Security Guidelines, 2023

24

security domains covered by the Information and Cyber Security Guidelines, each requiring documented controls and annual audit

IRDAI ICS Guidelines, 2023

Who must comply

Life, general, and health insurance companies

All public and private sector insurers operating in India, across life, general, and health insurance lines. The full scope of cybersecurity, corporate governance, and data localization obligations applies regardless of company size or market share.

IRDAI ICS Guidelines, 2023 & Corporate Governance Regulations, 2024

Foreign reinsurance branches

Foreign reinsurance branches (FRBs) operating in India are subject to the same cybersecurity and data governance framework as domestic insurers, including mandatory data localization and incident reporting to IRDAI and CERT-In.

IRDAI ICS Guidelines, 2023

Insurance intermediaries

Insurance brokers, corporate agents, web aggregators, insurance marketing firms, Insurance Self-Network Platforms (ISNPs), and Common Service Centres (CSCs). Individual agents and surveyors face limited applicability but must follow minimum internal security frameworks established by their principal insurers.

IRDAI ICS Guidelines, 2023 & Policyholders' Regulations, 2024

TPAs and service providers

Third Party Administrators, Motor Insurance Service Providers (MISPs), corporate surveyors, insurance repositories, and the Insurance Information Bureau of India. All entities within IRDAI's regulatory perimeter carry cybersecurity compliance obligations, and outsourcing arrangements face mandatory IRDAI inspection access.

IRDAI ICS Guidelines, 2023 & Outsourcing Regulations, 2024

AI system deployers across insurance

All AI and ML systems used for underwriting, claims processing, fraud detection, and customer service fall under existing regulatory obligations. The IRDAI AI Governance Working Group (announced June 2026) is drafting India's first formal AI governance framework for insurance, covering pre-deployment validation, post-deployment monitoring, and accountability for automated decisions.

IRDAI AI Governance Working Group, June 2026 & DPDP Act, 2023

What you must do

Board-level cybersecurity governance and CISO independence

ICS Guidelines, 2023 & Corporate Governance Regulations, 2024. The Board of Directors holds ultimate responsibility for information security and must approve the Information and Cyber Security Policy annually. A dedicated Chief Information Security Officer (CISO) must have direct access to the Board and CEO, establishing structural independence from operational IT teams. The Information Security Risk Management Committee (ISRMC), comprising the CTO, CISO, CRO, CSO, and CHRO, must meet at least twice annually and develop a three-year cybersecurity roadmap. A separate Risk Management Committee, chaired by an independent director, must meet at least four times per year.

→ Nexovern provides the continuous, correlated telemetry that boards and CISOs need for informed oversight, covering every AI system's runtime behavior, data access patterns, and policy adherence across the organization.

Six-hour incident reporting to IRDAI and CERT-In

ICS Guidelines, 2023 & Cyber Crisis Preparedness Circular, March 2025. All cyber incidents must be reported to both IRDAI and CERT-In within six hours of detection. Policyholder notification is mandatory for personal data breaches, with a 72-hour notification window under the DPDP Act. Entities must pre-empanel certified forensic experts to investigate incidents immediately. A conflict-of-interest safeguard prohibits organizations from conducting their own forensic investigations after identifying cyber risks. All system clocks must be synchronized with India's official NTP servers for forensic accuracy.

→ When an incident involves AI systems, Nexovern's prompt-level and OS-layer telemetry answers "what data was accessed, by which agent, and when" within the six-hour reporting window, replacing forensic guesswork with correlated evidence.

Data localization and 180-day log retention

Maintenance of Information Regulations, 2025. All ICT infrastructure logs, critical data, and business data must be stored on servers physically located in India. ICT and application logs require a continuous 180-day rolling retention period within Indian jurisdiction. When activities are outsourced to service providers outside India, all original policyholder records must continue to be maintained domestically. Cloud services are permitted only if customer data is encrypted, the cloud provider meets IRDAI-acceptable security standards, and the insurer retains full control and auditability.

→ Nexovern's monitoring identifies which AI agents send data to external endpoints, providing the visibility needed to verify that data localization requirements are met and that no AI workflow routes policyholder data outside Indian jurisdiction.

Annual cybersecurity audits across 24 security domains

ICS Guidelines, 2023. Independent cybersecurity audits covering all 24 security domains are mandatory every year. Audit reports must include findings summaries, non-compliance areas, risk ratings, and compliance checklists. Submission is due within 90 days after financial year-end or 30 days from audit completion, whichever is earlier. The 24 domains span data classification, access control, asset management, cryptographic controls, cloud security, incident management, business continuity, third-party provider management, mobile security, remote work, and monitoring and logging, among others.

→ Nexovern's continuous runtime records feed directly into annual audit engagements, providing auditors with correlated evidence of AI system behavior, access patterns, and control effectiveness across the 24 security domains.

AI governance: explainability, manual review, and outsourcing restrictions

DPDP Act, 2023 & Policyholders' Regulations, 2024. Under the DPDP Act, individuals affected by automated decisions have a right to explanation and a right to manual review. Under the Policyholders' Regulations, underwriting and claims decision-making functions cannot be outsourced, meaning AI systems making these decisions must operate under the insurer's direct governance. The AI Governance Working Group is designing pre-deployment validation and post-deployment monitoring requirements that will formalize accountability when automated systems produce errors in claims outcomes, fraud flags, or underwriting decisions.

→ Nexovern captures the full decision path for every AI-driven underwriting and claims interaction, providing the evidence trail that explainability requirements demand and supporting manual review processes with complete context.

DPDP Act alignment: consent, purpose limitation, and breach notification

DPDP Act, 2023 & Regulatory Sandbox Regulations, 2025. IRDAI's Regulatory Sandbox 2025 explicitly mandates DPDP Act compliance as a prerequisite for sandbox approval. Insurers must obtain explicit, informed consent before data collection or processing. Data may be collected only for specific purposes, and secondary use requires fresh consent. AI training data must be collected with appropriate consent. All data used by AI systems, including model outputs and decision logs, must be stored in India, and customer data processed by AI must be encrypted.

→ Nexovern's session-level records show whether each AI agent processed data only for the consented purpose, providing the evidence trail that purpose limitation and DPDP alignment demand.

Penalties for non-compliance

Rs 1 lakh to Rs 5 lakhs per day, capped at Rs 10 crore

For default in furnishing documents, non-compliance with IRDAI directions, or failure to maintain solvency margin. The 2025 Insurance Amendment Act raised the cap tenfold from the previous Rs 1 crore limit, with penalties accumulating daily for continuing defaults.

Insurance Act, 1938 (as amended 2025), Section 102

Rs 1 crore to Rs 5 crore for false information

Providing false information to IRDAI attracts a minimum penalty of Rs 1 crore, extending to Rs 5 crore for each instance of failure. The 2025 Amendment also grants IRDAI express power to order disgorgement of wrongful gains.

Insurance Amendment Act, 2025

Board supersession and license action

IRDAI can supersede an insurer's board and appoint an administrator. The composite licensing framework now allows license suspension as a remedial step before permanent revocation, giving IRDAI a graduated enforcement toolkit. Procedural safeguards require IRDAI to consider nature, gravity, duration, and repetitiveness before imposing penalties.

Insurance Amendment Act, 2025

Recent enforcement actions

Policybazaar Insurance Brokers received a Rs 5 crore penalty (August 2025) for 11 charges including biased product promotions and governance violations. Cybersecurity breach penalties totaling Rs 3.3 crore were imposed in July 2025. Tata AIG and LIC are under investigation for separate data breach incidents. Appeals may be filed before the Securities Appellate Tribunal (SAT) within 45 days.

IRDAI Enforcement Orders, 2024-2025

Key dates

01

April 24, 2023: Information and Cyber Security Guidelines

IRDAI issues comprehensive cybersecurity guidelines covering 24 security domains, mandating board-level accountability, CISO independence, six-hour incident reporting, and 180-day log retention. Governance and reporting requirements take effect immediately.

02

March 20, 2024: Corporate Governance Regulations

IRDAI notifies the Corporate Governance for Insurers Regulations, 2024, formalizing governance structures, mandatory board committees, quarterly meeting cadences, and minimum three independent directors. Compliance deadline for the accompanying Master Circular is June 30, 2024.

03

January 10, 2025: Regulatory Sandbox and Data Maintenance

IRDAI notifies the Regulatory Sandbox Regulations 2025, permitting controlled experimentation with AI/ML, blockchain, and chatbots while mandating DPDP Act compliance as a prerequisite. Simultaneously, the Maintenance of Information Regulations consolidate data governance and mandate India-based data centres.

04

February 5, 2026: Enhanced penalties operative

The Insurance Amendment Act, 2025 (receiving Presidential assent on December 20, 2025) commences, raising the maximum penalty from Rs 1 crore to Rs 10 crore and granting IRDAI disgorgement powers. Penalties fund the newly established Policyholders' Education and Protection Fund.

05

April 1, 2026: Fraud Monitoring Framework effective

The Fraud Monitoring Framework Guidelines, issued October 2025, take effect. The framework governs AI-assisted fraud detection oversight, requiring audit trails, explainability, and false-positive management for automated fraud systems.

06

June 19, 2026: AI Governance Working Group announced

IRDAI announces a seven-member working group chaired by Sandeep K. Shukla (Director, IIIT Hyderabad) with IRDAI CISO Deepak Gaikwad as Member Convener. The group is tasked with delivering India's first formal AI governance framework for insurance within three months.

07

~September 2026: AI governance recommendations expected

The Working Group's three-month deadline for delivering recommendations covering ethical AI use, pre-deployment audits, post-deployment monitoring, stress testing for AI models, and security controls against AI-driven automated attacks.

How Nexovern helps

IRDAI compliance for AI in insurance starts with knowing what you have

Every AI agent processing policyholder data in your environment is within scope. A Nexovern demo shows you where your AI systems operate today, what data they touch, and where the gaps are before the AI Governance Working Group's recommendations become binding.